#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Aritifacts of docker env of CVE-2020-8036

Test exploit of CVE-2021-44228

Docker-based RCE exploit demo for Log4Shell (CVE-2021-44228) with vulnerable Spring Boot app, malicious LDAP server, and payload delivery via JNDI…

Proof-of-concept local privilege escalation exploit for CVE-2024-1086 targeting Linux kernels v5.14–v6.6. Achieves root shell with 99.4% success rate…

CVE-2025-62215 exploit development using Claude Code Agent Team

Hands-on lab for CVE-2026-40072 — SSRF vulnerability in web3.py via CCIP Read (EIP-3668)

A lab for playing around with the Log4J CVE-2021-44228

Purple team exercise scripts demonstrating CVE-2025-59287, an unauthenticated RCE in WSUS via malicious deserialization payload injection into the…

Proof-of-concept exploit for CVE-2021-29447, an authenticated XXE vulnerability in WordPress 5.6-5.7. Includes lab setup, malicious WAV generation,…

A practical lab demonstrating the exploitation of a critical Remote Code Execution (RCE) vulnerability in Apache Struts2 (CVE-2017-5638) using Vulhub…

Docker-based lab demonstrating CVE-2017-8291 (GhostButt) exploitation via Python PIL/Pillow EPS image processing, with a vulnerable web application…

Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project…

Exploiting WordPress vulnerabilities (CVE-2025-34077), authentication bypass via cookie injection, and privilege escalation to root. Part of my…

A Proof-of-Concept (PoC) exploit for CVE-2018-16763 (Fuel CMS - Preauthenticated Remote Code Execution).

CVE-2020-35848 impacts Cockpit-CMS v1.7 due to unsafe handling of user inputs in authentication mechanisms, leading to remote code execution. This…

Non-weaponized PoC and checker for CVE-2024-32019, a local privilege escalation in Netdata's ndsudo helper. Assess exposure, validate patches, and…

GIT vulnerability | Carriage Return and RCE on cloning

XStream DoS CVE-2021-21341